QID 981031
QID 981031: Python (pip) Security Update for django-anymail (GHSA-hxf9-7h4c-f5jv)
webhooks/base.py in Anymail (aka django-anymail) before 1.2.1 is prone to a timing attack vulnerability on the WEBHOOK_AUTHORIZATION secret, which allows remote attackers to post arbitrary e-mail tracking events.
Successful exploitation of this vulnerability may affect the confidentiality, integrity, and availability of the targeted user.
Solution
Customers are advised to refer to GHSA-hxf9-7h4c-f5jv for updates pertaining to this vulnerability.
Vendor References
- GHSA-hxf9-7h4c-f5jv -
github.com/advisories/GHSA-hxf9-7h4c-f5jv
CVEs related to QID 981031
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| GHSA-hxf9-7h4c-f5jv | django-anymail |
|